CVE-2025-11235
MOVEit Transfer REST API does not require current password in order to initiate the password change process
Unverified Password Change vulnerability in Progress MOVEit Transfer on Windows (REST API modules).This issue affects MOVEit Transfer: from 2023.1.0 before 2023.1.3, from 2023.0.0 before 2023.0.8, from 2022.1.0 before 2022.1.11, from 2022.0.0 before 2022.0.10.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Productos afectados
Progress · MOVEit Transfer¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →